Find cloud misconfigurations in your Terraform before you deploy.
WAFPass scans your Infrastructure-as-Code in one command. No AWS account, no setup, no cloud credentials — just a clear list of what to fix before it reaches production.
Three steps to your first scan.
One PyPI package gives you the static-analysis engine.
pip install wafpass-corePoint WAFPass at your Terraform folder and get a JSON summary.
wafpass check . --output json | jq '.summary'A clear pass/fail count and per-control findings tell you exactly what to fix.
What a first finding looks like
WAFPass flags a public S3 bucket and shows the exact control and the fix.
S3 bucket public access block is disabled. Public buckets expose data to the internet.
resource "aws_s3_bucket_public_access_block" "public" {
bucket = aws_s3_bucket.public.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
Four outcomes that matter to leadership.
Turn cloud complexity into a structured, measurable conversation — from the boardroom to the engineering team.
Sovereign by design
Retain control of data, workloads, and infrastructure decisions — independent of any cloud provider.
Secure before deployment
Embed security and compliance checks directly into infrastructure-as-code workflows.
Audit-ready, always
Generate traceable reports and evidence packages mapped to 50+ compliance frameworks.
Cost transparency
Make cloud spend, waste, and optimization potential visible across teams and workloads.
Built for every stakeholder in the cloud journey.
Tech Leads & CTOs
Set a clear quality baseline and track improvement across teams.
Cloud Architects
Design workloads with a shared, vendor-neutral decision lens.
Platform & SRE Teams
Embed controls into pipelines and make best practices default.
Security & Compliance
Prove governance with evidence, not opinions.
Consultants & Auditors
Run repeatable, comparable assessments for clients.
Trusted by cloud practitioners.
WAF++ provides a stable foundation for digital applications and shows how technical precision and design sensitivity can be successfully combined.
WAF++ has great potential to become the perfect answer to real-world everyday questions from the technology, cloud & developer community.
For the first time we can show our board a single, vendor-neutral score for cloud workload quality instead of slide decks full of gut feeling.
WAFPass caught misconfigurations in Terraform before they reached production. That alone saved us a full audit cycle.
The sovereign pillar gives us a clear language for residency and control discussions with regulators and customers.
8 pillars. One coherent system.
For technical teams, WAF++ provides a complete architecture quality model — from security to sovereignty to AI-assisted operations.
Retain full control of data, workloads, and infrastructure. Avoid vendor lock-in and meet digital sovereignty requirements.
AI-assisted architecture reviews and policy-aware autonomous agents that operate cloud workloads safely.
Protect workloads against threats, misconfiguration, and unauthorized access.
Build systems that recover gracefully and serve users consistently at scale.
Two extra pillars for a world that classic frameworks weren't built for.
WAF++ takes the six proven Well-Architected pillars and adds the two that matter most for modern, regulated, AI-assisted cloud operations.
Sovereign
Digital sovereignty, data residency, and vendor independence. The first plus keeps your architecture under your control.
Agentic
Policy-aware autonomous agents and AI-assisted architecture reviews. The second plus makes the framework ready for the agentic era.
Compliance checks that run before the cloud.
The open-source WAFPass platform scans Terraform, AWS CDK, and more — no credentials, no API calls, just fast, traceable results.
git clone https://github.com/WAF2p/wafpass-core.git
For the full Docker Compose stack (CLI + Server + Dashboard) see the complete installation guide.
From code to compliance in three steps.
Build infrastructure-as-code the way you already do. WAF++ stays out of your workflow.
Static analysis checks every resource against WAF++ controls — no cloud credentials needed.
Export PDF reports, block violations in CI, and prove governance to auditors.
Built by the community
Ready to build cloud architecture with intention?
Join the community, read the docs, or run your first WAFPass scan today.